首页> 外文期刊>Information Security Technical Report >ESEAP: ECC based secure and efficient mutual authentication protocol using smart card
【24h】

ESEAP: ECC based secure and efficient mutual authentication protocol using smart card

机译:ESEAP:使用智能卡的基于ECC的安全有效的双向身份验证协议

获取原文
获取原文并翻译 | 示例
       

摘要

Smart card based user server mutual authentication framework is famous for safe communication via unfavorable and insecure communication system. The authenticated user and server communicate to each other and share information via Internet. Recently, Wang et al. suggested a lightweight password-assisted two factor authentication framework using smart card. We reviewed their scheme and observed that it does maintain security and privacy off-line password guessing attack and also impersonation attack. We proposed enhance elliptic curve cryptography(ECC) based authentication framework for the same environment. The proposed scheme ESEAP is secure resilience of many attractive security attributes and features like off-line password guessing attack, no password verifier-table, smart card loss attack, anonymity, mutual authentication, replay attack, impersonation attack, server spooling attack, no clock-synchronization attack, forward secrecy, insider attack, message authentication, provision of key agreement, parallel attack, sound repairability, no password exposure, timely typo detection, resistance to know attacks, password friendly, user unlinkability and server unlinkability. Further, the paper shows formal security analysis of the ESEAP which based on random oracle model. We compared the presented protocol with other related protocols in the same environment, and show that ESEAP is more efficient in terms of computation and communication cost. As a result, the presented protocol can be utilized over public communication channel.
机译:基于智能卡的用户服务器相互身份验证框架以通过不利且不安全的通信系统进行安全通信而闻名。经过身份验证的用户和服务器相互通信,并通过Internet共享信息。最近,Wang等人。建议使用智能卡的轻量级密码辅助两因素身份验证框架。我们审查了他们的方案,发现该方案确实维护了安全性和隐私性离线密码猜测攻击以及模拟攻击。针对相同的环境,我们提出了基于增强椭圆曲线密码学(ECC)的认证框架。提议的方案ESEAP具有许多有吸引力的安全属性和功能的安全弹性,例如离线密码猜测攻击,无密码验证表,智能卡丢失攻击,匿名,相互认证,重播攻击,模拟攻击,服务器假脱机攻击,无时钟等-同步攻击,前向保密性,内部攻击,消息身份验证,提供密钥协议,并行攻击,声音可修复性,无密码泄露,及时键入错误检测,抗已知攻击,密码友好,用户不可链接和服务器不可链接。此外,本文还展示了基于随机预言模型的ESEAP的正式安全性分析。我们将提出的协议与相同环境中的其他相关协议进行了比较,并表明ESEAP在计算和通信成本方面更为有效。结果,所提出的协议可以在公共通信信道上使用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号